Ransom

Ransom:Win32/Ymacco.AAA3 malicious file

Malware Removal

The Ransom:Win32/Ymacco.AAA3 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Ymacco.AAA3 virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Uses Windows utilities for basic functionality
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Likely virus infection of existing system binary

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom:Win32/Ymacco.AAA3?


File Info:

crc32: 3B54FB77
md5: ecc4eeb82ce659f15a0470d97659964f
name: upload_file
sha1: 2848f4988ea4e3ea75b4d3d3589fb15bb0c04bb5
sha256: a3c2207806f9be710f3a1d1cbf1149a708bb080946e2368c8e826f5cef2293e4
sha512: 09eed015175a508058661dbbb8c4d677786d296c7ebc82377ea7fd5bd2dfc3879d65d467842a20b2b36e8d9c1142563b8c183a761b4f364805eb3497f44036ab
ssdeep: 98304:68qSiwOhUqE82mcoS9oYx1RMdLlYcZLdWcmKza7P+c/sVvaHolX:hHEUK2mco8TRcYKRxmKubEVSoX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Ymacco.AAA3 also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanTrojan.GenericKD.43566381
FireEyeGeneric.mg.ecc4eeb82ce659f1
CAT-QuickHealTrojanRansom.Agent
McAfeeArtemis!ECC4EEB82CE6
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.43566381
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_80% (D)
TrendMicroRansom_Ymacco.R03BC0DH220
SymantecDownloader
APEXMalicious
AvastWin32:Malware-gen
GDataTrojan.GenericKD.43566381
KasperskyTrojan-Ransom.Win32.Agent.axwf
AlibabaRansom:Win32/generic.ali2000027
NANO-AntivirusTrojan.Win32.Drop.hpiquz
ViRobotTrojan.Win32.Z.Agent.6017536
RisingRansom.VHDLocker!1.C88A (CLOUD)
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKD.43566381 (B)
F-SecureTrojan.TR/Ransom.sbeqg
DrWebTrojan.MulDrop11.51552
ZillyaTrojan.Agent.Win32.1358755
Invinceaheuristic
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan-Ransom.VHDLocker
CyrenW32/Trojan.QLOM-6097
AviraTR/Ransom.sbeqg
MAXmalware (ai score=100)
Antiy-AVLTrojan[Ransom]/Win32.Agent
MicrosoftRansom:Win32/Ymacco.AAA3
ArcabitTrojan.Generic.D298C52D
ZoneAlarmTrojan-Ransom.Win32.Agent.axwf
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Agent.C4171247
BitDefenderThetaGen:NN.ZexaF.34144.@FW@amnQa!oi
ALYacTrojan.Ransom.Filecoder
TACHYONTrojan/W32.Agent.6017536.B
VBA32TScope.Malware-Cryptor.SB
MalwarebytesRansom.Vhd
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Filecoder.OBF
TrendMicro-HouseCallRansom_Ymacco.R03BC0DH220
TencentWin32.Trojan.Agent.Aojc
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
Ad-AwareTrojan.GenericKD.43566381
AVGWin32:Malware-gen
Cybereasonmalicious.88ea4e
Paloaltogeneric.ml
Qihoo-360Generic/HEUR/QVM19.1.E4A1.Malware.Gen

How to remove Ransom:Win32/Ymacco.AAA3?

Ransom:Win32/Ymacco.AAA3 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment